Russell Parrott | AI Governance & Geopolitical Risk Research

I’m an independent author and researcher examining the relationship between politics, geopolitics and AI governance, and its consequences for businesses outside the technology industry.

My work explores how governments and AI companies exercise power, shape standards and distribute responsibility and whether the protections they offer can be demonstrated in practice. This means examining political incentives, commercial interests, independent oversight and the ability of affected organisations to challenge decisions to obtain evidence and secure remedies.

These questions connect directly to everyday business concerns: who controls an AI service, what authority a business gives it, what happens when it fails and whether essential work can continue if access is changed, restricted or withdrawn. Dependencies on overseas providers, national policy, infrastructure and geopolitical relationships all form part of that examination.

Alongside this analysis, I develop and publish original reference standards, governance tests and analytical frameworks for assessing control, traceability, accountability and resilience. These provide practical ways to examine whether governance arrangements function under real operating conditions.

The writing is aimed at owners, managers and other decision-makers, including small businesses and sole traders, and uses plain business language. My purpose is to help readers understand how decisions made by governments and technology companies affect their own authority, exposure and ability to keep operating.

My research and reference work is published independently through Zenodo and other public repositories, where it is versioned, citable and open to scrutiny.

I do not provide consultancy or advisory services.

Writing is my profession. Under the pen name Cecil Atley, I also write the Rhys Maren historical mysteries, which centre on evidence, forgotten histories and the reconstruction of events from records left behind.

Standardized Definition of AI Governance

A public reference standard that defines AI governance as a measurable structural condition, moving beyond policy statements to test whether control, accountability, traceability and integrity can be demonstrated in practice across the AI lifecycle.

Learn about The Standardized Definition of AI Governance
Parrott, R. (2025) “The Standardized Definition of AI Governance”. Self-published via Zenodo. Available at: https://doi.org/10.5281/zenodo.17505286

Evidential Resilience Ratio (ERR)

A quantitative AI governance metric designed to measure how much of an AI system remains provable when models, APIs, vendors or other upstream dependencies change. ERR focuses on traceability, reconstructability, version fidelity and dependency proof to assess whether governance can survive change.

Learn about the Evidential Resilience Ratio Test
Parrott, R. (2025) “Evidential Resilience Ratio”. Zenodo. Available at: https://doi.org/10.5281/zenodo.17799428

External AI Withdrawal and Geopolitical Disruption Test

A practical governance test examining whether a business can maintain critical services if access to an external AI provider is suddenly restricted or withdrawn because of provider decisions, government action, sanctions, trade restrictions or geopolitical disruption.

Learn about External AI Withdrawal and Geopolitical Disruption Test
Parrott, R. (2026) “External AI Withdrawal and Geopolitical Disruption Test”. Zenodo. Available at: https://doi.org/10.5281/zenodo.22844995

The AI Protection Tests

A public reference framework for testing whether important AI protections actually work in practice, focusing on control, accountability, business dependence and effective oversight rather than relying on policies, promises or formal safeguards alone.

Learn about The AI Protection Tests
Parrott, R. (2026) “The AI Protection Tests”. Zenodo. Available at: https://doi.org/10.5281/zenodo.23012740
The Standardized Definition of AI Governance provides the foundation. It sets out what AI governance should mean in practice and how it can be tested, rather than relying only on policies, principles or statements of intent. Its focus is on whether control, accountability, human oversight, traceability and wider governance structures can actually be demonstrated.

The AI Protection Tests build on that foundation by asking whether important protections actually work in practice for the people and organisations affected by AI. They examine four areas: control for people who choose to use AI, accountability for people affected by AI they did not choose, business protection where organisations depend on AI providers, and effective independent oversight.

The Evidential Resilience Ratio (ERR) and the External AI Withdrawal and Geopolitical Disruption Test then address two more specific areas that broader governance frameworks may leave to implementation.

ERR focuses on evidence and auditability: if the technology changes, can the organisation still prove what happened? While the External AI Withdrawal and Geopolitical Disruption Test focuses on dependency and continuity: if an external AI service is restricted, withdrawn or becomes unavailable, can the organisation still operate?

Together, the four provide practical structural tests and measurements for turning broad AI governance requirements into questions that organisations can actually examine, evidence and act on.